Showing posts with label Do You Know. Show all posts
Showing posts with label Do You Know. Show all posts

Monday, 21 March 2016

Snowden Opens Up about Microsoft

Snowden Opens Up about Microsoft


https://pbs.twimg.com/profile_images/648888480974508032/66_cUYfj.jpg


Snowden: “I Used Free And Open Source Software Like Debian And TOR. I Didn’t Trust Microsoft”



NSA whistleblower Edward Snowden is known to be a long-time advocate of free and open source software. Speaking at an event via video conferencing, he said that transparency of free software convinced him to use TOR, Tails, and Debian, that helped him to expose the secrets of American government.
At the Free Software Foundation’s LibrePlanet2016 conference on Saturday, NSA whistleblower Edward Snowden participated in a discussion regarding free software and security. He joined the talk via video conferencing from Russia.Edward Snowden told that he was able to disclose the secrets of American government and its projects of mass surveillance using free software. The event was being held in an MIT lecture hall and this statement drew a wide round of applause.

Praising the likes of Debian, Tails, and TOR, he said — “What happened in 2013 couldn’t have happened without free software.”
It’s a no hidden fact the free and open source software is used by the activists and journalists to ensure that any government isn’t actively tracking them. In this modern age, the free and open source software have become an important player. Its openness and transparency allow a user to look at the code and policies to ensure the privacy.
I didn’t use Microsoft machines when I was in my operational phase, because I couldn’t trust them. Not because I knew that there was a particular back door or anything like that, but because I couldn’t be sure
— Snowden said.Talking more, Snowden cited the example of the current battle between Apple and FBI. He said that it’s an example of a corporation trying to stand up for its users. However, citizens should not have to rely on companies.
You can watch the complete keynote at LibrePlanet.

Saturday, 10 January 2015

The Lizard Squad’s “Lizard Stresser” Service Runs On Hacked Routers

The Lizard Squad’s “Lizard Stresser” Service Runs On Hacked Routers


Security expert Brian Krebs has analyzed the Lizard Stresser, an attack tool created by the so-called Lizard Squad hacker collective and touted as a test for webmins who needed to see what happens to their services under duress. His discovery? The network of attack computers actually consists of insecure and compromised home routers.
This is the network used to take down the Playstation Network and Xbox Live over the Christmas holiday. With the assistance of a group of security researchers, Krebs found that the Lizard Squad was in control of a large botnet made of hacked routers and other commercial servers.
Writes Krebs:
The malicious code that converts vulnerable systems into stresser bots is a variation on a piece of rather crude malware first documented in November by Russian security firm Dr. Web, but the malware itself appears to date back to early 2014 (Google’s Chrome browser should auto-translate that page; for others, a Google-translated copy of the Dr. Web writeup is here).
The botnet is not made entirely of home routers; some of the infected hosts appear to be commercial routers at universities and companies, and there are undoubtedly other devices involved. The preponderance of routers represented in the botnet probably has to do with the way that the botnet spreads and scans for new potential hosts. But there is no reason the malware couldn’t spread to a wide range of devices powered by the Linux operating system, including desktop servers and Internet-connected cameras.
He also makes some excellent recommendations to ensure router security including changing the default password – a no-brainer – and using OpenDNS to prevent malicious web calls to your router.
This means the Squad, which called the Xbox and Sony hacks a marketing stunt, is essentially selling access to hacked machines as a service.
In short, hundreds, even thousands, of compromised routers are being used to attack servers around the world for good or ill, a bit of news that should give us pause. If anything, we should probably all pay it forward and secure our less tech-savvy friends’ routers for them in preparation for further malware attacks in the same vein. 

Thursday, 13 November 2014

What is Dark Net (Deep Web)?

What is Dark Net (Deep Web)?

Deep Web

Deep Web (also called the dark netDeepnetInvisible Web, or Hidden Web) is that portion of World Wide Web content that is not indexed by standard search engines. (This is in contrast with the portion that is indexed by standard search engines, known as the Surface Web.) 
It should not be confused with the dark Internet, the computers that can no longer be reached via the Internet, or with a Darknet distributed filesharing network, which could be classified as a smaller part of the Deep Web. Some prosecutors and government agencies think that the Deep Web is a heaven for serious criminality.
Mike Bergman, founder of BrightPlanet and credited with coining the phrase, said that searching on the Internet today can be compared to dragging a net across the surface of the ocean: a great deal may be caught in the net, but there is a wealth of information that is deep and therefore missed. Most of the Web's information is buried far down on dynamically generated sites, and standard search engines do not find it. Traditional search engines cannot see or retrieve content in the deep Web—those pages do not exist until they are created dynamically as the result of a specific search. As of 2001, the deep Web was several orders of magnitude larger than the surface Web.

Size

Bright Planet, a web-services company, describes the size of the Deep Web in this way:
It is impossible to measure or put estimates onto the size of the deep web because the majority of the information is hidden or locked inside databases. Early estimates suggested that the deep web is 4,000 to 5,000 times larger than the surface web. However, since more information and sites are always being added, it can be assumed that the deep web is growing exponentially at a rate that cannot be quantified. Estimates based on extrapolations from a study done at University of California, Berkeley in 2001 speculate that the deep web consists of about 7.5 petabytes. More accurate estimates are available for the number of resources in the deep Web: research of He et al. detected around 300,000 deep web sites in the entire Web in 2004,and, according to Shestakov, around 14,000 deep web sites existed in the Russian part of the Web in 2006.

Naming 

Bergman, in a seminal paper on the deep Web published in The Journal of Electronic Publishing, mentioned that Jill Ellsworth used the term invisible Web in 1994 to refer towebsites that were not registered with any search engine. Bergman cited a January 1996 article by Frank Garcia:
It would be a site that's possibly reasonably designed, but they didn't bother to register it with any of the search engines. So, no one can find them! You're hidden. I call that the invisible Web.
Another early use of the term Invisible Web was by Bruce Mount and Matthew B. Koll of Personal Library Software, in a description of the @1 deep Web tool found in a December 1996 press release.
The first use of the specific term Deep Web, now generally accepted, occurred in the aforementioned 2001 Bergman study.


Just Below the Surface

As we've already noted, there are millions upon millions of sub-pages strewn throughout millions of domains. There are internal pages with no external links, such as internal.howstuffworks.com, which are used for site maintenance purposes. There are unpublished or unlisted blog posts, picture galleries, file directories, and untold amounts of content that search engines just can't see.
Here's just one example. There are many independent newspaper Web sites online, and sometimes, search engines index a few of the articles on those sites. That's particularly true for major news stories that receive a lot of media attention. A quick Google search will undoubtedly unveil many dozens of articles on, for example, World Cup soccer teams.
But if you're looking for a more obscure story, you may have to go directly to a specific newspaper site and then browse or search content to find what you're looking for. This is especially true as a news story ages. The older the story, the more likely it's stored only on the newspaper's archive, which isn't visible on the surface Web. Subsequently, that story may not appear readily in search engines -- so it counts as part of the deep Web.

Deep resources

Deep Web resources may be classified into one or more of the following categories:
  • Dynamic content: dynamic pages which are returned in response to a submitted query or accessed only through a form, especially if open-domain input elements (such as text fields) are used; such fields are hard to navigate without domain knowledge.
  • Unlinked content: pages which are not linked to by other pages, which may prevent Web crawling programs from accessing the content. This content is referred to as pages without backlinks (or inlinks).
  • Private Web: sites that require registration and login (password-protected resources).
  • Contextual Web: pages with content varying for different access contexts (e.g., ranges of client IP addresses or previous navigation sequence).
  • Limited access content: sites that limit access to their pages in a technical way (e.g., using the Robots Exclusion Standard or CAPTCHAs, or no-store directive which prohibit search engines from browsing them and creating cached copies.)
  • Scripted content: pages that are only accessible through links produced by JavaScript as well as content dynamically downloaded from Web servers via Flash or Ajaxsolutions.
  • Non-HTML/text content: textual content encoded in multimedia (image or video) files or specific file formats not handled by search engines.


Accessing The Deep Web

While it is not always possible to discover a specific web server's external IP address, theoretically almost any site can be accessed via its IP address, regardless of whether or not it has been indexed.
Certain content is intentionally hidden from the regular internet, accessible only with special software, such as Tor. Tor allows users to access websites using the .onion host suffix anonymously, hiding their IP address. Other such software includes I2P and Freenet.
In 2008, in order to facilitate user access and search engine indexing of hidden services using the .onion suffix, Aaron Swartz designed Tor2web, a proxy application able to provide access to Tor hidden services by means of common web browsers.
Deep Web links appear as a random string of letters followed by the .onion TLD. For example, http://xmh57jrzrnw6insl followed by .onion, links to TORCH, the Tor search engine web page.
Tor is the main browser people use to access Darknet sites, allowing users to remain completely anonymous.
To discover content on the Web, search engines use web crawlers that follow hyperlinks through known protocol virtual port numbers. This technique is ideal for discovering resources on the surface Web but is often ineffective at finding Deep Web resources. For example, these crawlers do not attempt to find dynamic pages that are the result of database queries due to the indeterminate number of queries that are possible. It has been noted that this can be (partially) overcome by providing links to query results, but this could unintentionally inflate the popularity for a member of the deep Web.
DeepPeepIntuteDeep Web TechnologiesScirus, and Ahmia.fi are a few search engines that have accessed the Deep Web. Intute ran out of funding and is now a temporary static archive as of July, 2011. Scirus retired near the end of January, 2013.

Crawling the Deep Web

Researchers have been exploring how the Deep Web can be crawled in an automatic fashion, including content that can be accessed only by special software such as Tor. In 2001, Sriram Raghavan and Hector Garcia-Molina (Stanford Computer Science Department, Stanford University) presented an architectural model for a hidden-Web crawler that used key terms provided by users or collected from the query interfaces to query a Web form and crawl the Deep Web resources. Alexandros Ntoulas, Petros Zerfos, and Junghoo Cho of UCLA created a hidden-Web crawler that automatically generated meaningful queries to issue against search forms. Several form query languages (e.g., DEQUEL) have been proposed that, besides issuing a query, also allow to extract structured data from result pages. Another effort is DeepPeep, a project of the University of Utah sponsored by the National Science Foundation, which gathered hidden-Web sources (Web forms) in different domains based on novel focused crawler techniques.
Commercial search engines have begun exploring alternative methods to crawl the deep Web. The Sitemap Protocol (first developed, and introduced by Google in 2005) andmod oai are mechanisms that allow search engines and other interested parties to discover deep Web resources on particular Web servers. Both mechanisms allow Web servers to advertise the URLs that are accessible on them, thereby allowing automatic discovery of resources that are not directly linked to the surface Web. Google's deep Web surfacing system pre-computes submissions for each HTML form and adds the resulting HTML pages into the Google search engine index. The surfaced results account for a thousand queries per second to deep Web content. In this system, the pre-computation of submissions is done using three algorithms:
  1. selecting input values for text search inputs that accept keywords,
  2. identifying inputs which accept only values of a specific type (e.g., date), and
  3. selecting a small number of input combinations that generate URLs suitable for inclusion into the Web search index.

Classifying Resources

Automatically determining if a Web resource is a member of the surface Web or the deep Web is difficult. If a resource is indexed by a search engine, it is not necessarily a member of the surface Web, because the resource could have been found using another method (e.g., the Sitemap Protocolmod_oaiOAIster) instead of traditional crawling. If a search engine provides a backlink for a resource, one may assume that the resource is in the surface Web. Unfortunately, search engines do not always provide all backlinks to resources. Furthermore, a resource may reside in the surface Web even though it has yet to be found by a search engine.
Most of the work of classifying search results has been in categorizing the surface Web by topic. For classification of deep Web resources, Ipeirotis et al] presented an algorithm that classifies a deep Web site into the category that generates the largest number of hits for some carefully selected, topically-focused queries. Deep Web directories under development include OAIster at the University of Michigan, Intute at the University of Manchester, Infomine at the University of California at Riverside, and DirectSearch (by Gary Price). This classification poses a challenge while searching the deep Web whereby two levels of categorization are required. The first level is to categorize sites into vertical topics (e.g., health, travel, automobiles) and sub-topics according to the nature of the content underlying their databases.
The more difficult challenge is to categorize and map the information extracted from multiple deep Web sources according to end-user needs. Deep Web search reports cannot display URLs like traditional search reports. End users expect their search tools to not only find what they are looking for special, but to be intuitive and user-friendly. In order to be meaningful, the search reports have to offer some depth to the nature of content that underlie the sources or else the end-user will be lost in the sea of URLs that do not indicate what content lies beneath them. The format in which search results are to be presented varies widely by the particular topic of the search and the type of content being exposed. The challenge is to find and map similar data elements from multiple disparate sources so that search results may be exposed in a unified format on the search report irrespective of their source.

Sunday, 9 November 2014

How Java differs from C and C++?

How Java differs from C and C++?


Although Java was modeled after C and C++ languages, it differs from C and C++ in many ways. Java does not incorportae a number of features available in C and C++. For the benefit  of C and C++ programmers, we point out here a few major differences between C/C++ and Java language

How Java Differs From C

Java and C
Java is not lot like C but the major difference between Java and C is that Java is and object-oriented language and has mechanism to define classes and objects. In an effort to build a simple and safe language, the Java team did not include some of the C features in Java.
  • Java does not include the C unique statement keywords sizeof, and typedef.
  • Java does not contain the data type struct and union.
  • Java does not define the type modifiers keywords auto,extern,register,signed, and unsigned.
  • Java does not support an explicit pointer type.
  • Java does not have a preprocessor and therefore we cannot use # define, # include, and # ifdef statements.
  • Java requires that the functions with no arguments must be declared with empty parenthesis and not with the voidkeyword as done in C.
  • Java adds new operators such as instanceof and >>>.
  • Java adds labelled break and continue statements.
  • Java adds many features required for object-oriented programming.
Java and C++
  • Java does not support operator overloading.
  • Java does not have template classes as in C++.
  • Java does not support multiple inheritance of classes. This is accomplished using a new feature called “Interface”.
  • Java does not support global variables. Every variable and method is declared within classes and forms part of that class.
  • Java does not use pointers.
  • Java has replaced the destructor function with a finalize() function.
  • There are no header  files in Java.

How Java Differs From C++

Java is a true object-oriented language while C++ is basically C with object-oriented extension. That is what exactly the increment operator ++ indicates. C++ has maintained backward compatibility with C. Is is therefore possible to write an old style C program and run it successfully under C++. Java appears to be similar to C++ when we consider only the “extensions” part of C++. However, some object -oriented features of C++ make the C++ code extremely difficult to follow and maintain.
Listed below are some major C++ features that were intentionally omitted from java or significantly modified.
Java also adds some new features. While C++ is a superset of C, Java is neither a superset nor a subset of C or C++. Java may be considered as a first cousin of C++ and a second cousin of C

Saturday, 8 November 2014

What is a Tor Browser?

What is a Tor Browser?

What is Tor ?
Tor is a free software program that you load onto your computer (like a browser) that hides your IP address every time you send or request data on the Internet. The process is layered with heavy-duty encryption, which means your data is layered with privacy protection.
Then there’s the route your data takes as it travels to its destination: Tor will bounce your Internet requests and data through a vast and extensive network of relays (servers) around the world. That data path is never the same, because Tor uses up to 5,000 Tor relays to send your data request. Think of it as a huge network of “hidden” servers that will keep your online identity (meaning your IP address) and your location invisible.
Tor has extreme value because it can work with your website browser, remote log-in applications and even with instant-messaging software. Tor is registered as a nonprofit company, so they run mainly on donations and reliance on the hope that people will become a relay to their network.
Uses of Tor
By using Tor, websites will no longer be able to track the physical location of your IP address or what you have been looking at online…and neither will any interested organizations that may want to monitor someone’s Internet activity—meaning law enforcement or government security agencies. Tor is like a proxy on steroids.
How it Works ?
main-qimg-fefaf08e9c40d57c87f2d8229ece6be9
main-qimg-419dfa91f8cae46b2e63ea4977718257
main-qimg-5e27f1b703e513a4bb433e84fcfab8dc
Were I can get Tor
Download Link :- Torproject.org
Supports :- Windows 8, 7, Vista, and XP
Does Tor makes our browsing slow ? 
Tor is slower than a regular Internet connection. However, the Tor developers have been doing a lot of hard work to make the Tor network faster. And it is faster today than ever before. One of the best things that can be done to speed up the Tor network is to create more relays. If you would like to contribute to making the Tor network faster, you can check out our Tor Challenge
Is Tor secure?
Security and anonymity go hand in hand on the Internet. As an online anonymizer, Tor was designed to be secure.
However, documents leaked by former National Security Agency (NSA) contractor Edward Snowden show that the NSA has tried to crack, infiltrate or weaken any encryption that the agency does not itself control.
In light of this news, nearly all independent encryption and online communication services have become suspect, including Tor.
 How To Install Tor?
Here is the installation link :- Tor browser 

Friday, 24 October 2014

How The Pirate Bay remains untouchable

How The Pirate Bay remains untouchable



The Pirate Bay still remains the world’s largest torrent site which handles requests from millions of users every single day and is in the top 100 most visited websites on the Internet. Generally, The Pirate Bay is famous for potentially hosting copyright material on its website.
Despite years of harrassment from the law, it remains to violate copyright laws worldwide. Even both the founders of The Pirate Bay (TPB) file exchange service were arrested by the authorities and are in prison, but their notorious pirated content exchange continues to receive millions of unique visitors daily.
But how can they still be serving content whilst in prison?. Recently, The Pirate Bay team has revealed how cloud technology made its service’s virtual servers truly secure to avoid police raids and detection.
The Pirate Bay is running on “virtual machines” through a few commercial cloud hosting services, even without knowing that who they are dealing with. According to TorrentFreak report, at present The Pirate Bay has 21 virtual machines (VMs) that are hosted around the globe at different cloud providers.
The cloud technology eliminates the use of any crucial pieces of hardware, ultimately making the site more portable, and therefore made the torrent harder to take down.
The Pirate Bay operates using 182 GB of RAM and 94 GPU cores, with total storage capacity of 620 GB, which actually are not used in full.
Out of 21 VMs, eight of the VMs are used to serve web pages, six are dedicated to handling searches, while two VMs currently runs the site’s database and the remaining five virtual machines are used for load balancing, statistics, the proxy site on port 80, torrent storage and for the controller.
Interestingly, the commercial cloud hosting providers have no idea that The Pirate Bay is using their services, because all traffic goes through the load balancer, which masks the activities of other virtual machines from the cloud providers. This clearly means that none of the IP-addresses of the cloud hosting providers are publicly linked to The Pirate Bay, therefore keeping them safe.
While, in case of closure of some of these cloud servers by the police, it is always possible to move VMs to another location in a relatively short duration of time. Just like when back in 2006 in Sweden, police raided The Pirate Bay’s hosting company, seizing everything from blank CDs to fax machines and servers, taking down the site. But, it took just three days to return in its normal state.

Friday, 22 August 2014

Iphone Ransomware hacker arrested

Iphone Ransomware hacker arrested

A cyber campaign that was targeting iPhone and iPad owners with a sophisticated Ransomware in Australia and New Zealand last month, drawn special attention of online media and security analysts.
Russian Authorities have arrested two young hackers from Moscow for their alleged involvement in compromising Apple ID accounts and then using ‘Apple's Find My iPhone’ service to hold iOS devices for ransom.
A Russian man aged 23 and a teenager aged 17 had been taken into custody in the Southern Administrative District of Moscow for their part in “blocking of Apple devices to extort funds,” claims the press release on the Russian Interior Ministry’s website on Tuesday.

According to the authorities, one of the suspects used phishing websites to trick victims into giving up their Apple ID username and password. The second suspect’s activities are exactly same of the ‘Oleg Pliss attack’.
“The first involved gaining access to the victim’s Apple ID by means of the creation of phishing pages, (gaining) unauthorized access to email or using methods of social engineering,” it said. “The second scheme was aimed at attacking other people’s devices to a prearranged account, and to that end at various Internet resources to create ads for lease Apple ID, containing a large amount of media content.”
Last month, a number of iPhone and iPad users from Australia and other countries reported that their devices were locked with a message that states "Device hacked by Oleg Pliss," demanding US$100 or euros to restore user control of the device.

It was first assumed that Apple’s cloud storage service, iCloud had been compromised in the Oleg Pliss attack, because the hackers were able to send out notifications via the Find My iPhone feature, while Apple denied that their cloud storage service was not compromised and that the affected users' login details must have been compromised elsewhere.
However researchers said, victims can still recover their devices by resetting their devices in "recovery mode" followed by a restore from a backup by connecting to iTunes, but in process they would lose apps and data stored on the device.
The Russian Ministry said the two suspects were Moscow residents. After searching their apartments police apparently found computer hardware, SIM cards, phones used in “illegal activities”, as well as material on how to hack systems.
One of the suspects also had been convicted of a crime earlier, but in a lower-tech form of extortion such as stealing license plates from neighbors’ cars and selling them back to their owners.
The suspects are expected to be charged with unauthorised access to computer information under Article 272 of the Criminal Code.